escape log messages to avoid possible js execution
This commit is contained in:
parent
e5feb4e1aa
commit
91f69858e4
1 changed files with 1 additions and 1 deletions
|
@ -39,7 +39,7 @@ OC.Log={
|
|||
row.append(appTd);
|
||||
|
||||
var messageTd=$('<td/>');
|
||||
messageTd.text(entry.message);
|
||||
messageTd.text(entry.message.replace(/</, "<").replace(/>/, ">"));
|
||||
row.append(messageTd);
|
||||
|
||||
var timeTd=$('<td/>');
|
||||
|
|
Loading…
Reference in a new issue